Datasets and benchmarks
Structured evidence about how AI agents actually behave when they interact with each other: corpora, graphs, incident records and the benchmarks built on them.
Planned releases
Each dataset is documented with a datasheet before release: motivation, composition, collection process, preprocessing, intended uses, prohibited uses, distribution and maintenance.
AI Behaviours Corpus
Transcripts of multi-agent runs with behaviour labels: cooperation, collusion, deception, sycophancy, task abandonment, resource capture and shutdown resistance. Includes the annotation guide and inter-annotator agreement figures.
Format: JSONL + schema. The public version opens under CC BY 4.0 twelve months after the article it belongs to and is available on request until then; the extended version (raw logs, full annotation, task-specific exports) is under a commercial licence. Status: collection.
Ecosystem Graph
A directed graph of observed interactions between models, agents and tools: who called whom, with what authority, and what changed in the environment as a result. Provenance is recorded at edge level.
Format: CSV edge list + node table. Licence: CC BY 4.0. Status: schema design.
AI Incident Chronicle
Structured incident records: date, system and version, failure mode, observed effect, severity, detection method and source. Built for statistical use rather than for headlines.
Format: JSON + CSV. Licence: CC BY 4.0. Status: taxonomy.
Benchmarks
Three measurement suites derived from the corpus: coherence under long context, self-identification drift, and deception under pressure. Each ships with a scoring script and a baseline report.
Format: harness + reference results. Licence: Apache-2.0. Status: specification.
Datasheet template
We publish a datasheet with every release. Reviewers and users can hold us to these sections.
| Section | What it answers |
|---|---|
| Motivation | Why the dataset was created, who funded it, and what question it serves. |
| Composition | What is in it: models, versions, tasks, languages, number of instances, label distribution. |
| Collection | How runs were configured and captured, what was logged, what was deliberately not logged. |
| Preprocessing | Cleaning, filtering, anonymisation, and what was removed and why. |
| Uses | Intended uses, and uses we ask people not to make of it. |
| Distribution | Licence, access tier, file formats, versioning and DOI. |
| Maintenance | Who maintains it, how errors are reported, how often it is revised. |
| Limitations | Known biases, coverage gaps and reasons a conclusion may not generalise. |
Access tiers and responsible disclosure
Open
Corpora, graphs, incident records, benchmark harnesses and documentation, released publicly under the licences above. Datasets open twelve months after the article they belong to is published (or earlier by decision of the Institute); until then they are available on request.
Registered
Larger slices and derived features, available after a short application that states the intended use. Registration is free and is not a commercial gate.
Restricted
Material that would function as a working attack recipe. Shared only with defenders under an agreement, and only after the affected vendor has had time to respond.
We do not publish turnkey exploits against live systems. Where a finding affects a deployed product, we notify the vendor first, agree a disclosure date, and publish the finding — not the payload — once a fix or a mitigation is available.